Commit Graph
90 Commits
Author SHA1 Message Date
aneurinandClaude Sonnet 5 8bb9f05559 Fix container registry login: GITEA_TOKEN never grants package access
CI / php-tests (pull_request) Successful in 22s
CI / frontend-build (pull_request) Successful in 35s
Build / build-and-push (push) Failing after 13m53s
The auto-injected secrets.GITEA_TOKEN doesn't work for pushing to
Gitea's container registry regardless of the workflow's own
permissions: block -- a known Gitea limitation, not a config mistake
(go-gitea/gitea#23642). Switch to a manually-configured
CONTAINER_REGISTRY_PASSWORD secret (a personal access token with
write:package scope) instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 12:58:03 +01:00
aneurinandClaude Sonnet 5 950d116e53 Add image build/push workflows, scoped to test/build/push only
CI / php-tests (pull_request) Successful in 19s
CI / frontend-build (pull_request) Successful in 37s
Build / build-and-push (push) Failing after 4s
Builds and pushes to Gitea's container registry on push to main
("latest"/"previous", to avoid accumulating per-commit tags) and on
git tag push (tagged to match). Deployment is intentionally out of
scope here -- that work is being split into a separate project.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 12:38:05 +01:00
aneurinandClaude Sonnet 5 2370b06913 Add frontend build and dependency audits to CI
CI / php-tests (pull_request) Successful in 29s
CI / frontend-build (pull_request) Successful in 42s
Nothing previously checked that a PR still produces a working frontend
build -- add a job that type-checks and builds the Vue app. Also run
composer audit / npm audit so known CVEs in dependencies fail the build
rather than going unnoticed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 10:39:19 +01:00
aneurinandClaude Sonnet 5 16f94293ab Make the per-owner project cap configurable via env
CI / php-tests (pull_request) Successful in 19s
Self-hosters shouldn't be stuck with a hardcoded 100-project limit;
MAX_PROJECTS_PER_OWNER now controls it, defaulting to 0 (unlimited).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 09:34:08 +00:00
aneurinandClaude Sonnet 5 e59890618e Install Node in the CI job container before checkout
CI / php-tests (pull_request) Successful in 22s
actions/checkout is a JS action and needs a node binary on PATH; the
php:8.3-cli-alpine job container doesn't ship one, so checkout was
failing with "node: executable file not found in $PATH".

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 10:32:15 +01:00
aneurinandClaude Sonnet 5 6faf4a72df Add Gitea Actions workflow to run PHPUnit on pull requests
CI / php-tests (pull_request) Failing after 5s
Runs the backend test suite against PHP 8.3 for every PR targeting
main, so branch protection can require it to pass before merging.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 09:23:55 +01:00
aneurinandClaude Sonnet 5 5c8f2dbf07 Un-hard-wrap all Markdown documentation
Every prose paragraph and list item was manually wrapped at ~80-100
columns; joined each back into a single line. Headings, table rows,
and fenced code blocks are untouched -- tables already had one row per
line, and wrapping inside a code fence is the code's own formatting,
not something this applies to.

Also fixed two pre-existing typos this surfaced (both from wrapping
without leaving the space that was actually intended): a missing space
in "{ challenge_id, options }" and a stray "+ TypeScript" that had
accidentally been written as if it were a new line, in web/README.md
and README.md respectively.

Code comments are explicitly out of scope for this -- left exactly as
they were.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 02:29:08 +01:00
aneurinandClaude Sonnet 5 f1309b4c10 Rebuild the Docker image on Alpine: ~735MB -> ~89MB
Stage 2 was php:8.3-apache (Debian), which compiles PHP from source
with --with-apxs2 for mod_php -- that base image alone is 719MB of
our 735MB, before any app code. Replaced with alpine:3.24 + apk's own
prebuilt php83/php83-apache2/apache2 packages: same architecture (one
process, mod_php, .htaccess-driven rewriting), no fpm/nginx rewrite
needed.

- docker/apache.conf: rewritten for Alpine's apache2 (mod_rewrite ships
  but isn't loaded by default; a different default document root/log
  paths). Logs redirected to stdout/stderr so `docker logs` still shows
  them -- Alpine's own defaults write to a real file under ServerRoot,
  unlike the official Debian image's symlinked paths.
- docker/entrypoint.sh: su-exec instead of su -- BusyBox's su doesn't
  take the same -c/user argument order as the GNU one the previous
  entrypoint relied on. Also moved earlier in the Dockerfile (with the
  other rarely-changing setup, before COPY . .) so it no longer re-runs
  on every build for a file that essentially never changes.
- Composer's binary is still borrowed from the official composer:2
  image via multi-stage COPY, not apk's own `composer` package, which
  turned out to pull in an entire second PHP interpreter (php85) as a
  dependency just to run itself.
- ext-iconv needed adding explicitly (symfony/polyfill-mbstring depends
  on it; the official Debian image bundles it by default, apk doesn't).

Verified against the real compose stack, not just that it builds: apk
install; composer install; migrations on startup; PHPUnit 88/88 (runs
on the host, but confirms nothing else broke); and by hand, all
through the actual container -- health check, SPA fallback for unknown
routes, static assets served directly, the API's 401 guard, and a full
magic-link -> verify -> JWT -> authenticated project create/list round
trip via the real Mailpit catcher.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 02:15:39 +01:00
aneurinandClaude Sonnet 5 82e8ee6c36 Trim .dockerignore to everything the build context doesn't need
Verified against the Dockerfile's actual COPY instructions -- src/,
bin/, migrations/, public/, docker/, composer.json/lock, and web/'s
own build inputs are the only things either stage touches. Everything
else that COPY . . would otherwise sweep in now excluded: tests/,
phpunit.xml, docker-compose.yml, .env.example, and web/'s own
non-build files (README.md, .env.example, .gitignore, .dockerignore).

web/.dockerignore itself is dead either way -- the build context is
the repo root (docker-compose.yml's `build: .`), not web/, so it was
never actually consulted by anything -- but there's no harm leaving it
for a hypothetical standalone frontend build.

Verified: rebuilt the image, confirmed the excluded paths are genuinely
absent from it, app still serves and 401s correctly unauthenticated,
and PHPUnit (run from the host, unaffected either way) still 88/88.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:54:41 +01:00
aneurinandClaude Sonnet 5 ef9669dc57 Catch up web/README.md and two stale comments to current code
web/README.md's Layout section hadn't been touched since early in the
session: it was missing ManageMenu.vue, CardManageMenu.vue,
StatusManager.vue, useDialog.ts, and four of the ten views
(ProjectExploreView, ProjectKanbanView, CardView, CardConfigureView)
entirely, still described CardRow as inline-editable-with-a-delete-
button, and still claimed the top-level <RouterView> was keyed by
plain route.path (true before this session's Explore/Kanban route
split, wrong after -- see App.vue's routeKey). The Inbox section also
still gated the post-drag cards refresh on route.name === 'project'
alone, from before Explore itself could send a card there.

Also fixed two lingering "all tasks" references (the tab's name before
it became "Explore") in a stores/cards.ts comment and a style.css one.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:48:14 +01:00
aneurinandClaude Sonnet 5 fb67b57807 Reorganize docs: simple README + organized docs/
Removed docs/stage-1-auth-api.md -- an early planning doc, badly out
of date (predates passwordless auth, statuses, the inbox, and
everything after).

README.md is now just: what this is, a pointer to docs/, an end-user
getting-started guide (Docker up, first-time login via the bundled
Mailpit catcher, adding a passkey), and provenance -- everything else
it used to carry moved out:

- docs/api.md -- the full REST API reference (auth, passkeys,
  projects, cards, statuses, error shape) + the curl walkthrough.
- docs/setup.md -- running without Docker, every environment
  variable, the test suite.
- docs/architecture.md -- backend file layout; points to
  web/README.md for the frontend, which already documented itself in
  enough depth to stand alone.
- docs/history.md -- the stage-by-stage feature log, with a new row
  for this session's refactoring work (which hadn't been logged yet).
- docs/README.md -- an index tying the above together.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:41:55 +01:00
aneurinandClaude Sonnet 5 b00ec7addd Squash all migrations into one clean initial schema
Replaces 001-011 (create/alter/rebuild/backfill, in the order features
landed) with a single 001_initial_schema.sql that creates every table
in its final shape directly -- no password_hash (added then dropped),
no project description (added then dropped), cards already shaped as
the global-inbox-with-a-CHECK-constraint design rather than rebuilt
into it, no data-migration/backfill statements (nothing to backfill
against a schema created fresh).

This is a pre-release project with no data worth preserving, so the
dev database (and the storage volume's generated JWT key with it) was
wiped rather than migrated -- confirmed the fresh schema matches
exactly (same tables/columns as before, minus the two dropped columns)
and the app works end to end against it. PHPUnit's in every run
already builds its database from migrations/*.sql from scratch, so the
suite needed no changes and is unaffected either way: 88/88.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:32:27 +01:00
aneurinandClaude Sonnet 5 fb59a54938 Drop the unused project description field entirely
It never got a UI home on the frontend -- removed from ProjectView a
few sessions back and never restored anywhere -- so it was a fully
live field (validated, stored, returned by the API, covered by tests)
with no consumer.

- Migration 011: ALTER TABLE projects DROP COLUMN description.
- ProjectRepository: description dropped from ProjectRow, SELECT,
  create() and update() -- update() is now just a rename (string, not
  a $fields array; there was never more than one editable field once
  this left).
- ProjectController: store()/update() no longer accept or validate
  it; update() drops the "provide at least one of title, description"
  branch, since title is unconditionally the only field now.
- Frontend Project type, root README's API docs and curl example.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:25:53 +01:00
aneurinandClaude Sonnet 5 367a98308a Extract a shared ManageMenu; add notFoundOr for the repeated 404 pattern
ManageMenu.vue holds what ProjectManageMenu and CardManageMenu had
copy-pasted between them almost verbatim: the dropdown, the confirm
modal, both useDialog wirings, menuOpen/confirmingDelete/deleting
state. Each is now a thin wrapper supplying only what's genuinely
entity-specific -- the Configure route, the delete labels, and (as
confirmDelete) what deleting actually does, since that differs more
than the UI around it (which stores to refresh, where to navigate).
The confirmation body text comes through the default slot, since a
project's names its card count and a card's doesn't.

notFoundOr(e, notFoundMessage, fallbackMessage) in lib/api.ts replaces
the identical "404 -> fixed message, else -> the error's own message,
else -> a fallback" block that ProjectView, ProjectConfigureView,
CardView, and CardConfigureView had each written out by hand.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:25:37 +01:00
aneurinandClaude Sonnet 5 6c7b78ad4b Explore: cards can be dragged out to the inbox
One-directional drag support, joining the shared "kanban" group:
put: false and sort: false mean a card can leave Explore's list (to
unfile it via the sidebar's inbox) but the list can't receive a drop
itself (there's no status to assign an incoming card) or be reordered
by dragging (it's sorted by name regardless).

sortedCards moves from a computed to a ref rebuilt by a watch --
<draggable> splices its bound list in place as the user drags, which a
plain computed would just discard on its next recomputation. No local
@change handler is needed: the splice already happens locally, and the
inbox's own handler (AppSidebar) persists the move and reloads this
project's cards regardless of which side of the drag it's reacting to.

AppSidebar: widened the "is a project open" check for the post-drag
cards refresh back to both project routes (Explore's list is now also
a place a card can leave from), and reused the same route-name set
already defined for the sidebar's project switcher.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 01:04:50 +01:00
aneurinandClaude Sonnet 5 9505d20e0d Add-passkey form: one line, "Passkey label" placeholder, shorter label
Switches from the stacked .form pattern to .field-row, same as the
other single-line forms (input + fit-width button); the visible
"Label" span becomes a placeholder/aria-label instead, and the button
reads "Add passkey" rather than "Add a passkey".

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:57:47 +01:00
aneurinandClaude Sonnet 5 d1de9f50f5 Remove the per-row delete button from Explore's cards
Matches KanbanCard, which never had one -- deleting a card lives on
its own view now (CardManageMenu's "Delete card"), reachable by
clicking through from either list.

Cleaned up what that leaves unused: the cards store's remove() (its
only caller), and .card-row__delete's styling.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:54:36 +01:00
aneurinandClaude Sonnet 5 80ff31748b Explore card rows: match the kanban card's hover style
.card-row now highlights its border-color on hover, same as
.kanban-card, instead of tinting .card-row__link's background --
a card should look the same hovered whichever view shows it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:51:24 +01:00
aneurinandClaude Sonnet 5 8641c3d013 Make Explore and Kanban real routes, not tab state
/projects/:id (name "project") is now Explore; /projects/:id/kanban
(name "project-kanban") is Kanban. ProjectView.vue becomes a layout:
header + sub-nav, loading the project and its cards (both children
need the cards list) and rendering the active one via <RouterView>.
ProjectExploreView.vue and ProjectKanbanView.vue hold what used to be
each tab's own template/logic; Kanban additionally loads its own
statuses, since Explore has no use for them.

The sub-nav is now RouterLinks (active state matched on route.name),
not buttons toggling local state.

App.vue: the top-level <RouterView> was keyed by the full route path
to force a fresh instance per project/card id -- with Explore/Kanban
now separate paths under one layout, that would also remount the
layout (and re-fetch the project) on every tab switch. Keyed by the
matched route's top-level path + params instead, which is the same
value for both of a project's child routes.

AppSidebar: the project switcher and the inbox-drag refresh both used
to check route.name === 'project' for "this project is open" -- fixed
to cover both routes for the switcher, and narrowed to
'project-kanban' specifically for the inbox-drag refresh, since Kanban
is the only route with a draggable list a card could have moved
to/from.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:46:17 +01:00
aneurinandClaude Sonnet 5 81900f4d06 Rename the "All tasks" tab to "Explore"
Also refreshed web/README.md while touching this section: fixed the
project/project-configure header descriptions to describe the current
inline .title-back arrow (they still described the old separate "Back
to project" button), and added a "Card detail" section documenting
CardView/CardConfigureView/CardManageMenu, which had none.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:36:38 +01:00
aneurinandClaude Sonnet 5 4cd59234e2 All tasks tab: match the new-card form layout used everywhere else
Was the stacked .form pattern (visible "New card" label above a
full-width input). Now .kanban__new, same as the kanban columns and
sidebar inbox: compact field + placeholder/aria-label in place of the
visible label, on one line with the icon button. Kept form--new-card
for the border-top separator above it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:32:50 +01:00
aneurinandClaude Sonnet 5 e55641bcba Card configure view: "Edit text"/"Save" -> "Rename card"/"Rename"
Matches the project rename form's wording ("Renaming…"/"Rename").

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:30:26 +01:00
aneurinandClaude Sonnet 5 55fa9fef56 Split card editing/delete out into a CardConfigureView, mirroring projects
CardView is now just the read view -- header (inline back arrow +
card text) and its status badge, no tabs (there's nothing to tab
between). New CardConfigureView (/cards/:id/configure) holds the
"Edit text" form that used to live inline in CardView.

New CardManageMenu, mirroring ProjectManageMenu: a "Manage" dropdown
with "Configure" (hidden while already on the configure view) and
"Delete card" (with its own confirmation modal). Both CardView and
CardConfigureView use it in their header actions, same as the project
view and its own configure view.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:29:06 +01:00
aneurinandClaude Sonnet 5 8a0befa1c7 Stretch the add-icon buttons to their row's height; bigger glyph
Dropped the hardcoded 2rem height -- .field-row/.kanban__new are flex
rows with the default align-items: stretch, so the button now fills
to match its compact field's actual height instead of a guessed value
that had to be kept in sync with it. Also bumped the "+" from 1.1rem
to 1.4rem.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:23:53 +01:00
aneurinandClaude Sonnet 5 ca3be38f0c Give the add-icon buttons a border matching the compact field
A borderless icon next to a bordered input looked adrift. Same
1px solid var(--border) as .field, turning var(--accent) on hover
(alongside the icon itself, as before).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:22:00 +01:00
aneurinandClaude Sonnet 5 f5cc82a2f4 Ghost-style the add-card/status icon buttons; convert the last one
- .btn-icon: transparent background, muted icon that turns accent on
  hover -- matching .title-back's treatment exactly, instead of a
  solid accent-filled square.
- The "all tasks" tab's "Add card" button is now the same .btn-icon
  as the kanban/inbox/status ones, so every "add" action in the app
  looks and behaves the same.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:20:32 +01:00
aneurinandClaude Sonnet 5 7ce0f156f0 Replace the compact "Add" buttons with a plus icon
The kanban column, sidebar inbox, and add-status forms all had their
own "Add" submit button; with a column-per-status now, that's a lot of
identical labels on screen at once. Replaced with a small square "+"
icon button (.btn-icon), each keeping a descriptive title + aria-label
(dynamic, so it reads "Adding…" while the request is in flight) since
the visible glyph alone isn't an accessible name.

.btn-icon is excluded (":not(.btn-icon)") from the generic submit
button rule and the .field-row/.kanban__new compact-button overrides,
rather than out-specificity'd -- same reasoning as .field's low
specificity against input:focus: it shouldn't depend on source order
which one wins. .kanban__new's own override is now dead (both of its
two buttons are icons) and removed outright.

Left the "Add card" button on the "All tasks" tab as text -- it's a
lone, full-width primary action in a larger form, not one of several
compact icon-sized ones crowded together.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:16:38 +01:00
aneurinandClaude Sonnet 5 19ccb8f881 Add a "new card" form to each kanban column
Each column gets its own form at the bottom (styled like the sidebar
inbox's), creating the card directly in that status, appended after
its existing cards.

- API: POST /projects/{id}/cards takes an optional status_id, which
  must belong to the project (422 otherwise); omitted, it still
  defaults to the project's first status as before. Position is
  already "end of that status" for free -- createInProject() already
  ranks by (owner, project, status).
- cards store: add() takes an optional statusId, forwarded as
  status_id when given.
- ProjectView: one draft string per status (keyed by status id) so
  typing in one column doesn't touch another's, mirroring the
  per-status independence the columns already have for reordering.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:10:52 +01:00
aneurinandClaude Sonnet 5 e598d4ef57 Change-email input: "New email" -> "New email address"
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:06:20 +01:00
aneurinandClaude Sonnet 5 b04935ada9 Make the change-email form a single line, like the rename forms
Switches from the stacked .form pattern to .field-row: the input and
its submit button now sit side by side, the button sized to fit its
text rather than stretched full width -- matching the project rename
and add-status forms.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:05:06 +01:00
aneurinandClaude Sonnet 5 4947ebdf38 Use the card view's inline back arrow on every other heading
Generalized .card-view__back into .title-back and applied it to:

- ProjectView: arrow back to the dashboard, inline before the title
  (previously no back link at all here -- the app bar's brand already
  covers it, but this is more discoverable and matches the others).
- ProjectConfigureView: arrow back to the project, replacing the
  separate "Back to project" button that used to sit in the actions
  corner next to Manage.
- ProfileView: arrow back to the dashboard, replacing the plain-text
  link removed in an earlier commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-05 00:02:09 +01:00
aneurinandClaude Sonnet 5 fb329bf693 Add a dedicated card view; make card text no longer inline-editable
Clicking a card -- in the "all tasks" list, a kanban column, or the
inbox -- now opens /cards/:id instead of editing the text in place:

- CardRow's text is now plain (its RouterLink wraps the text + status
  badge; the delete button stays a sibling so it isn't nested inside
  the link). KanbanCard is now itself a RouterLink.
- New CardView.vue: header follows the project view's layout, but the
  back link sits inline inside the title (before the card's text)
  rather than off in the actions corner, since it isn't paired with a
  manage menu here. Inbox cards have no project to link back to, so
  they go to the dashboard instead. Below the header, an "Edit text"
  section (styled like the project rename form) replaces the inline
  editing that used to live in the list row, and a delete button in
  the header actions replaces CardRow's per-row delete for cards
  reached via kanban/inbox (which never had one).
- No backend changes: GET/PATCH/DELETE /cards/{id} already existed.
- Renamed .card-row__status to the more general .status-badge, now
  shared by the list row and the card view.
- cards store: dropped setText, now unused now that editing goes
  through a direct PATCH + store refresh in CardView instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 23:51:06 +01:00
aneurinandClaude Sonnet 5 c2c988d928 Remove the redundant back-to-dashboard link on the profile view
The app bar's brand/logo already goes to the dashboard, same as the
other app pages.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 23:42:48 +01:00
aneurin 83471e55d4 Extract StatusManager, dedupe ColumnChange type, add useDialog composable
- Pull the status-management feature (drag reorder, add, delete with
  reassignment) out of ProjectConfigureView into its own StatusManager
  component. It fetches its own status list independently, so the view
  is left with just page chrome and the rename form (316 -> 106 lines).
- Define ColumnChange once in lib/cardOrder.ts instead of duplicating
  the same type in AppSidebar.vue and ProjectView.vue.
- Add composables/useDialog.ts for the Escape-to-close + focus-on-open
  behaviour shared by every confirm/reassign modal (and, without a
  focus target, plain dropdown menus). Used by ProjectManageMenu's
  delete-confirmation modal + its own menu, and StatusManager's
  reassignment modal.
2026-09-04 23:35:33 +01:00
aneurinandClaude Sonnet 5 a3462af005 Fix the broken input focus outline, unify input styling, tokenize scales
The root cause of 'some inputs show a focus outline, most don't': the
global input:focus/textarea:focus/select:focus rule (outline:none,
border-color: accent) has specificity (0,0,1,1). Every per-component
rule shaped '.wrapper input { border: 1px solid var(--border) }' (.form
input, .field-row input, .kanban__new input, .sidebar__select select,
.modal__field select) ties it exactly, and -- being unconditional --
silently won that tie by simply appearing later in the file, so the
input's border stayed var(--border) forever regardless of focus. Only
two controls escaped: .project-card__name-input (a class applied
directly to the element, (0,0,1,0), too low to ever win the tie) and
.card-row__text (has its own .card-row__text:focus, (0,0,2,0),
genuinely higher). Confirmed with a live computed-style test against
the real stylesheet before and after.

Fix: one canonical .field class (plus .field--compact for inline 'add'
rows and the sidebar, .field--autosize for the dashboard's JS-grown
textarea), applied directly to the <input>/<textarea>/<select> itself
in every view -- structurally immune to the same tie, since a bare
class can never out-specificity input:focus. This also collapses five
near-duplicate rules (each with its own padding/radius/font-size) into
one definition, and fixes .kanban__new input's stray
background: var(--surface) (every other field uses var(--bg); this one
nearly matched its own var(--surface) sidebar panel).

Also: .btn-danger hardcoded #b3261e/#fff instead of the already-
existing var(--error)/var(--accent-text) tokens, so danger buttons
didn't adapt in dark mode like every other error-coloured element;
now they do. Added .field:disabled styling (opacity/cursor), matching
buttons -- latent until now since no input bound :disabled yet.

Second pass, promoting repeated-but-consistent raw values to tokens:
- border-radius: 6/7/8/10/12/999px -- the stray 7px (.sidebar__link)
  folded into the 6px tier -- become --radius-sm/md/lg/xl/pill.
- disabled/ghost opacity: 0.6 was used for every disabled button
  except .status-row__delete's 0.4 (now unified) and drag-ghost states'
  0.5 (semantically different, kept separate) -- --opacity-disabled/
  --opacity-ghost.
Font-size and spacing values also repeat but don't reduce to a clean
scale without arbitrary judgement calls either way -- left alone.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 22:07:35 +01:00
aneurinandClaude Sonnet 5 a85bb182c7 De-duplicate controller boilerplate: owned-project lookup, reorder validation
requireOwnedProjectId() was copy-pasted identically in CardController
and CardStatusController; ProjectController's own
requireOwnedProject() was the same lookup, just returning the full
row instead of the id. New abstract ProjectScopedController (extends
Controller) holds one copy of both, and all three controllers now
extend it instead of Controller directly, forwarding their
ProjectRepository to its constructor.

Separately, CardController::reorder() (card_ids) and
CardStatusController::reorder() (status_ids) each had the same inline
'must be an array of ids, no duplicates' check. Both now call a new
Validator::intIdArray(), which does the same shape check once.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:45:17 +01:00
aneurinandClaude Sonnet 5 accc6a273c Centralize the current-timestamp SQL expression
"strftime('%Y-%m-%dT%H:%M:%SZ', 'now')" was a private nowExpr()
method copy-pasted identically in CardRepository, CardStatusRepository
and ProjectRepository, and inlined as a raw literal directly in
PasskeyRepository, WebAuthnChallengeRepository, UserRepository and
EmailVerificationRepository -- 7 files, ~12 occurrences of the same
string. Now one Database::nowExpr() static method (Support/Database
already being the natural home for SQLite-specific concerns), used
everywhere a repository sets a timestamp explicitly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:41:25 +01:00
aneurinandClaude Sonnet 5 029c05c46f Fix the mobile project-head layout with Grid instead of flex
The previous flex fix (column-reverse + stretch + justify-content) was
silently a no-op: its media query was placed earlier in the file than
.project-head's own base rule, so at equal specificity the later base
rule (align-items: flex-start, no flex-direction override) always won
the cascade regardless of viewport -- the buttons never actually
moved or stretched on mobile.

Replaced with grid-template-areas: 'title actions' on desktop
becomes a single column, 'actions' over 'title', below 768px, with
.project-head__actions given justify-self: end so it (and both the
Back/Manage buttons or the lone Manage button inside it) sits flush
right once it's the full row width. Verified with real screenshots at
375px on both ProjectView and ProjectConfigureView -- buttons stay on
one line top-right, the long title wraps beneath at full width.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:30:49 +01:00
aneurinandClaude Sonnet 5 91c0e8d6af Make the magic-link resend cooldown configurable
EmailVerifier::RESEND_INTERVAL_SECONDS was a hardcoded class constant
shared (via a copy-of-a-constant) by AuthController and
EmailVerificationController. It's now a constructor param
(resendIntervalSeconds, default 60, same as before) sourced from
Config -- new MAGIC_LINK_RESEND_SECONDS env var, default unchanged.

Docker Compose sets it to 0, so magic links resend immediately during
local development instead of waiting out the throttle.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:30:41 +01:00
aneurinandClaude Sonnet 5 4a9717caa5 Keep the header buttons right-aligned once the title wraps below
.project-head__actions stretches full width on mobile along with the
title (align-items: stretch), but its own content was left-aligned by
default. Add justify-content: flex-end there under the same
breakpoint, and wrap ProjectView's ProjectManageMenu in a
.project-head__actions div (it wasn't before) so both views share one
selector for this instead of ProjectView needing its own.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:18:26 +01:00
aneurinandClaude Sonnet 5 ba84c0e81b Mobile: stack project-head instead of squeezing it, wrap headings cleanly
.project-head (title + action buttons, shared by ProjectView and
ProjectConfigureView) was a plain flex row at every width, so on a
narrow screen the title and the Manage/Back buttons fought over space
instead of wrapping. Below 768px it's now flex-direction:
column-reverse -- the buttons (last in the DOM in both views) render
on top on one line, and the title wraps to as many lines as it needs
underneath, full width.

Also add a global h1/h2/h3 overflow-wrap: break-word so a long,
unbroken heading (a project title with no spaces, say) wraps instead
of overflowing its container, without breaking ordinary multi-word
headings mid-word. Drops .project-head__title's now-redundant own
word-break rule, since it's an <h1> and the global rule covers it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:15:47 +01:00
aneurinandClaude Sonnet 5 d4420f7fe0 Relabel the project name button 'Rename'
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:11:54 +01:00
aneurinandClaude Sonnet 5 038322e975 Relabel the configuration view's name section 'Rename project'
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:10:57 +01:00
aneurinandClaude Sonnet 5 eb1f6055f0 Document that Profile now renders wide
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:09:47 +01:00
aneurinandClaude Sonnet 5 f8c52f8103 Drop two more unneeded width caps
- .tabs__panel--narrow (42rem, the project view's 'All tasks' tab):
  removed the class and its rule, same reasoning as the config
  sections -- the page around it is already full-width.
- Profile now sets meta.wide, so it uses .app__main--wide instead of
  the default .app__main's 32rem cap, matching the dashboard/project/
  configure views instead of sitting narrow like the login form.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:09:31 +01:00
aneurinandClaude Sonnet 5 b51d70b447 Let config sections fill the container width
Drop .config-section's 32rem cap -- the project name and status forms
now stretch to whatever width .card.project actually has instead of
sitting narrower than the header above them for no reason.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:06:25 +01:00
aneurinandClaude Sonnet 5 0eaa100d97 Relabel the project name button 'Update'
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:04:42 +01:00
aneurinandClaude Sonnet 5 ed07ea442d Put the Save name button beside the input, fit to its width
Matches the status 'Add' form immediately below it: renamed the
shared row layout from .status-list__new to .field-row (it now backs
both forms) and switched the project name form to it -- input grows,
button sits to its right sized to its own label instead of stretching
full width underneath. Dropped the visible 'Name' label in favour of
a placeholder + aria-label, mirroring the status form exactly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:03:57 +01:00
aneurinandClaude Sonnet 5 ea169ebed0 Move project renaming from the project view to configuration
- ProjectView: title is now a plain <h1>, no longer inline-editable
  (dropped titleDraft/saveTitle/patchProject and the input markup --
  nothing else used patchProject).
- ProjectConfigureView: new 'Project name' section above 'Statuses',
  a small PATCH /api/projects/:id form. On success it also calls the
  projects store's fetchProjects(), since the dashboard grid and the
  sidebar's project dropdown read from that store and otherwise
  wouldn't pick up the new name (or the project's new alphabetical
  position) until some unrelated reload.
- style.css: dropped the now-dead .project-head__title input rules
  (both views render a plain heading now); .project-head__title gains
  word-break so a long static title still wraps instead of overflowing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 21:01:27 +01:00
aneurinandClaude Sonnet 5 c5ffdae2cd Group Back-to-project and Manage together, styled alike
Moves the back link from the far left to sit immediately left of the
Manage button (both now top right, in a new .project-head__actions
row), and switches it from .btn-secondary to .menu__toggle so the two
are visually identical rather than just similar.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 20:58:13 +01:00